PCChecker: Harding Windows Security Configurations

PCChecker: Harding Windows Security Configurations
复制标题

DOI:
10.1109/iccit.2008.250
复制
发表时间:
2008-11
期刊:
2008 Third International Conference on Convergence and Hybrid Information Technology
影响因子:
--
通讯作者:
Kang-San Kim;Jung-Min Kang;DoHoon Lee
Kang-San Kim;Jung-Min Kang;DoHoon Lee
中科院分区:
其他
文献类型:
--
作者:
Kang-San Kim;Jung-Min Kang;DoHoon Lee

文献摘要

被引文献

相似文献

由于蠕虫、病毒、间谍软件等攻击都是针对客户端PC的,这可能会影响整个组织的安全,因此最终用户的PC安全已经引起了人们的关注。许多PC安全解决方案,如补丁管理系统(PMS),AV(反病毒),AS(反间谍软件)等已经传播到最终用户。然而,如果没有Windows操作系统的安全配置,所有的解决方案都不能有效。窗口安全配置取决于最终用户的自由裁量权。用户实际上不知道他们必须配置什么才能使他们的PC安全。此外,没有标准的方式来表示安全级别或分数,可以帮助了解他们的PC有多安全。在本文中,我们提出了一个强制性的方法来加强Windows的安全配置和安全评分机制,使用CVSS(常见的漏洞评分系统)。
PC security for end users has been emerging concern because many attacks such as worm, virus, spyware and so on are targeting client PCs, which can affect overall organization's security. Many PC security solutions such as patch management system (PMS), AV (anti-virus), AS (antispyware) and so on have been disseminated to end users. However without secure configuration of Windows operating systems, all solutions can not be effective. Window security configuration depends on discretionary efforts of end users. The users actually do not know what they have to configure to make their PCs in safe. Moreover, thers is no standard way of representing the safety level or score that can help understand how safe their PCs are. In this paper, we present a mandatory method to harden Windows security configurations and a safety scoring mechanism using CVSS (common vulnerability scoring system).